Privacy-Preserving Access Control for Electronic Health Record Systems
Keywords:
Electronic Health Records (EHR), Privacy Preservation, Access Control, Healthcare Security, Role Based Access Control, Attribute-Based Encryption, Patient Privacy, Data Confidentiality, Authentication, Healthcare Information SystemsAbstract
The rapid adoption of Electronic Health Record (EHR) systems has significantly improved the management,
storage, and sharing of patient medical information among healthcare providers. However, ensuring the privacy
and confidentiality of sensitive health records remains a critical challenge due to increasing concerns regarding
unauthorized access, data breaches, and regulatory compliance. Privacy-preserving access control mechanisms
have emerged as an effective solution to safeguard patient information while maintaining secure and efficient
data accessibility. This paper presents an overview of privacy-preserving access control techniques employed in
Electronic Health Record systems, emphasizing role-based access control, attribute-based access control,
encryption-based access policies, and patient-centric authorization models. The study discusses the importance
of secure authentication, fine-grained authorization, and cryptographic approaches for protecting medical data
against unauthorized disclosure. Furthermore, existing challenges, including scalability, interoperability,
emergency access, and policy management, are examined. The proposed framework highlights the integration of
privacy-preserving mechanisms with access control strategies to improve confidentiality, integrity, and
availability of healthcare information. The study concludes that combining cryptographic techniques with flexible
access control models can significantly enhance the security and privacy of Electronic Health Record systems
while supporting efficient healthcare services.


